Rampline
Effective April 19, 2026 · v3.1

Privacy policy, written for humans.

Your prospect data and reply history are sensitive — for you and for the people your agent writes to. We treat both like production data.

No ads, ever

We do not sell data or embed ad-tech. The company runs on subscriptions, not attention.

SOC 2 Type II

Audited annually. AES-256 at rest, TLS 1.3 in transit, KMS-managed keys.

One-click export

Your accounts, messages, and reply history are yours. Download or delete from the product.

What this document is

Rampline Labs, Inc. ("Rampline", "we", "us") is a Delaware corporation headquartered in San Francisco, California. This policy explains what information we collect when you use rampline.co and the Rampline outbound agent, how we use it, and the rights you have over it.

We wrote this the way we wish every privacy policy were written: in plain language, in the order a curious engineer would actually read, with citations to the underlying processors you are delegating trust to.

Data we collect

Account data — name, work email, company, and password hash. Supplied by you at sign-up.

Outbound data — the accounts and contacts your agent sources, the signals it detects, the messages it drafts and sends, and the replies it receives on your behalf. Stored encrypted at rest (AES-256) and in transit (TLS 1.3).

Product analytics — anonymized event data (page views, feature use, click paths) captured via first-party instrumentation. We do not share this with ad networks.

Device & log data — browser, OS, IP address, and approximate region, logged only for security and abuse prevention.

How we use it

To operate Rampline — scoring accounts, drafting and delivering messages, processing replies, booking meetings against your calendar, and rendering your pipeline dashboard.

To improve the product — aggregate metrics, signal-source evaluation, and scoring calibration. Your message content and reply data are never used to train publicly available generative models.

To communicate — transactional emails (sign-up, reset, receipts), product updates if you opt in, and a short monthly founders digest you can unsubscribe from in one click.

To keep you safe — detecting abuse, preventing account takeover, complying with lawful requests.

Sub-processors

We list our sub-processors publicly and notify customers in-product 30 days before adding a new one. As of this writing: Amazon Web Services (US-West-2 primary, US-East-1 DR), LiveKit (voice infrastructure), Anthropic and OpenAI (inference), Stripe (billing), PostHog (product analytics, self-hosted), Linear (support).

All sub-processors are bound by our standard Data Processing Addendum. EU and UK transfers rely on Standard Contractual Clauses and supplementary measures documented in our trust center.

Retention

Raw signal data — 90 days by default. You can shorten this to 7 days or extend to 1 year per workspace.

Message and reply history — retained for the life of your account, because suppression and follow-up depend on it.

Backups — rolling 30-day encrypted backups, segregated from primary data.

Deletion — upon request we purge personal data within 30 days, except where we must retain it for tax, legal, or fraud-prevention reasons.

The levers you actually control

If you are a resident of the EU, UK, California, Colorado, Virginia, Connecticut, Utah, or any state with a comparable statute, you have the rights of access, portability, correction, deletion, and restriction.

Use the in-product privacy panel to export or delete your data without contacting us. If you cannot access the panel, email privacy@rampline.co. We respond within 15 business days, usually same-day.

Security

SOC 2 Type II report available under NDA. Penetration tests quarterly by an independent firm; most recent report dated February 2026.

All traffic is TLS 1.3. All stored data is encrypted with AWS KMS-managed keys. SSO (Google, Microsoft, Okta) and SCIM provisioning available on Scale plans.

Report vulnerabilities at security@rampline.co. PGP key on the trust center. We run a coordinated disclosure program with rewards up to $10K.

Contact

Privacy questions · privacy@rampline.co

Data Protection Officer · dpo@rampline.co

Postal mail · Rampline Labs, Inc., 2201 Valencia St, Suite 210, San Francisco, CA 94110, USA

Something unclear?

Ask privacy@rampline.co — we read every email.

Color scheme toggle